Prosecution Insights
Last updated: August 16, 2026
Application No. 18/758,325

SYSTEMS AND METHODS FOR SMART VERIFICATION

Final Rejection §102§103
Filed
Jun 28, 2024
Examiner
TRUONG, THONG P
Art Unit
2433
Tech Center
2400 — Computer Networks
Assignee
Stripe Inc.
OA Round
2 (Final)
82%
Grant Probability
Favorable
3-4
OA Rounds
1y 5m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
408 granted / 495 resolved
+24.4% vs TC avg
Strong +15% interview lift
Without
With
+15.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
16 currently pending
Career history
514
Total Applications
across all art units

Statute-Specific Performance

§101
11.0%
-29.0% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
24.2%
-15.8% vs TC avg
§112
8.3%
-31.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 495 resolved cases

Office Action

§102 §103
DETAILED ACTION 1. This action is responsive to an amendment filed on 1/23/2026. 2. Claims 1-11 and 21-29 are pending. Claims 1 and 21 are independent. Response to Arguments 3. Applicant's arguments filed 1/23/2026 have been fully considered; however, they are not persuasive based on new ground(s) of rejection. Notice that rejection under 35 U.S.C. 112 has been removed due to amendment. Claim Rejections - 35 USC § 102 4. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 5. The following is a quotation of 35 U.S.C. 102 which forms the basis for all obviousness rejections set forth in this Office action: (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. 6. Claims 1-5, 9, 11, 21-25 and 29 are rejected under 35 U.S.C. 102 as being anticipated by Toth (US PG Pub. 2020/0184048). As regarding claims 1 and 21, Toth discloses A server comprising: a processor [para. 33]; and a memory, wherein the memory stores instructions that, when executed by the processor [para. 33], cause the processor to: receive a first input identifying an entity attempting to access a first service [para. 44; receiving a first authentication request]; determine, using a machine learning model, a first risk score of the entity, by processing one or more parameters [para. 50; determining a deviation score]; identify, based on the first risk score, a second input request for the entity [para. 57; identifying an additional authentication challenge]; transmit the second input request to the first service [FIG. 5 and para. 55; transmitting a second authentication challenge]; receive a second input from the entity corresponding to the second input request [FIG. 5 and para. 55; receiving user input in responding the second authentication challenge]; determine, using the machine learning model, a second risk score of the entity by processing the second input and data corresponding to the second input request [FIG. 5 and para. 55; determining whether a user pass or fail the second authentication challenge]; determine a set of risk levels that the second risk score maps to [FIG. 5 and para. 55; determining whether a user pass or fail the second authentication challenge]; and (1) allow the entity access to the first service in response to determining that the second risk score maps to a first set of risk levels [FIG. 5 and para. 55; allowing access to the resource if the second authentication is pass]; or (2) restrict the entity from accessing the first service in response to determining that the second risk score maps to a second set of risk levels [FIG. 5 and para. 55; [FIG. 5 and para. 55; restricting access to the resource if the second authentication is failed]. As regarding claims 2 and 22, Toth further discloses The server of claim 1, wherein the first input comprises a request to access a feature of the first service [para. 7, 25 and 43-44; receiving user’s request to access one or more secured resources]. As regarding claims 3 and 23, Toth further discloses The server of claim 1, wherein the instructions further cause the processor to: map, at least, (1) a type of service and a determined risk score to one or more input requests and (2) a type of service of the first service and the first risk score to a mapped input request; and identify the mapped input request as the second input request [para. 53 and 60; mapping a type of access service and the deviation score to the request]. As regarding claims 4 and 24, Toth further discloses The server of claim 1, wherein the entity restricted from accessing the first service [para. 44; user initially needs to be authenticated using a first authentication to gain access], the instructions further cause the processor to [repeat similar steps recited in claims 1 and 21, respectively]: determine, based on the second risk score, a third input request, different from the second input request, for the entity to access the first service [para. 50; determining a deviation score]; transmit the third input request to the first service [FIG. 5 and para. 55; transmitting a second authentication challenge]; receive a third input from the entity corresponding to the third input request [FIG. 5 and para. 55; receiving user input in responding the second authentication challenge]; determine, using the machine learning model, a third risk score of the entity, by processing the third input and data corresponding to the third input request [FIG. 5 and para. 55; determining whether a user pass or fail the second authentication challenge]; determine the set of risk levels that the third risk score maps to [FIG. 5 and para. 55; determining whether a user pass or fail the second authentication challenge]; and (1) allow the entity access to the first service in response to determining that the third risk score maps to the first set of risk levels [FIG. 5 and para. 55; allowing access to the resource if the second authentication is pass]; or (2) restrict the entity from accessing the first service in response to determining that the third risk score maps to the second set of risk levels [FIG. 5 and para. 55; [FIG. 5 and para. 55; restricting access to the resource if the second authentication is failed]. As regarding claims 5 and 25, Toth further discloses The server of claim 1, wherein the first input comprises data automatically retrieved from a user interface used to attempt access to the first service [para. 32 and 57; receiving user interaction data via a user interface]. As regarding claims 9 and 29, Toth further discloses The server of claim 1, wherein the one or more parameters comprise one or more of: an access history of the entity for a second service [para. 25]; a type of access when attempting to access the first service [para. 25 and 48-51; determining a deviation score based on user behavior profile derived from previous interaction and the requested event type (e.g. balance inquiry, funds transfer, bill pay, and/or the like)]; and a feature of the first service. As regarding claim 11, Toth further discloses The server of claim 1, wherein the first input comprises one or more of: an indication of a location of the entity [para. 25 and 49]; an IP address of the entity [para. 25]; a User Agent (UA) string identifying a browser used by the entity to attempt to access the first service; and a type of operating system used by the entity when attempting to access the first service. As regarding claim 22, Toth further discloses The computer-implemented method of claim 21, wherein the first input comprises a request to access a feature of the first service [para. 44; a request to login]. As regarding claim 23, Toth further discloses The computer-implemented method of claim 21, wherein identifying, based on the first risk score, comprises: mapping, at least, (1) a type of service and a determined risk score to one or more input requests and (2) a type of service of the first service and the first risk score to a mapped input request; and identifying the mapped input request as the second input request [para. 53 and 60; mapping a type of access service and the deviation score to the request]. Claim Rejections - 35 USC § 103 7. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 9. Claims 6 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Toth (US PG Pub. 2020/0184048) in view of Yampolskiy (US PG Pub. 2016/0173521). As regarding claims 6 and 26, Toth discloses determining the first risk score of the entity [para. 25 and 48-51; determining a deviation score]. Toth does not explicitly disclose retrieve a previous risk score associated with the entity; and process the previous risk score and the one or more parameters, using the machine learning model, to update the previous risk score to the first risk score. However, Yampolskiy discloses it [para. 88, 92 and 99-100]. It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Toth’s system to further comprise the missing claim features, as disclosed by Yampolskiy, in order to improve identification of risk. 10. Claims 7, 8, 10, 27 and 28 are rejected under 35 U.S.C. 103 as being unpatentable over Toth (US PG Pub. 2020/0184048) in view of O’Brien (US PG Pub. 2017/0103230). As regarding claims 7 and 27, Toth does not explicitly disclose that the second input request includes a field for an alphanumeric identifier associated with a form of identification for the entity. However, O’Brien discloses it [para. 42-42]. It would have been obvious to one of ordinary skill in the art at the time the effective filing of the invention to modify Toth’s system to further comprise the missing claim features, as disclosed by O’Brien, to allow the user to select a preferred user authentication methods from a plurality of user authentication options. As regarding claim 8, Toth and O’Brien further discloses The server of claim 7, wherein the field allows for an alternative form of identification for the entity to be provided by the entity [O’Brien FIG. 2A and para. 54-55; user can select different categories of authentication information]. As regarding claims 10 and 28, Toth and O’Brien further discloses The server of claim 1, wherein the second input request comprises a request for a document identifying the entity [O’Brien para. 31, 34 and 52-55; identity document]. Conclusion Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THONG P TRUONG whose telephone number is (571)270-7905. The examiner can normally be reached on M-F 8:30AM - 5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 57127267986798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /THONG TRUONG/ Examiner, Art Unit 2433 /JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Jun 28, 2024
Application Filed
Oct 27, 2025
Non-Final Rejection mailed — §102, §103
Jan 09, 2026
Interview Requested
Jan 16, 2026
Examiner Interview Summary
Jan 23, 2026
Response Filed
Jun 26, 2026
Final Rejection mailed — §102, §103
Aug 03, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701128
Network Authentication Evaluation
2y 5m to grant Granted Aug 04, 2026
Patent 12701135
SYSTEM AND METHOD FOR OMNICHANNEL SOCIAL ENGINEERING ATTACK AVOIDANCE
2y 10m to grant Granted Aug 04, 2026
Patent 12694121
LIMITING A NUMBER OF ILLEGITIMATE INTERRUPTS FROM SWITCHING A CENTRAL PROCESSING UNIT TO A SYSTEM MANAGEMENT MODE
3y 3m to grant Granted Jul 28, 2026
Patent 12695785
PASSIVE DETECTION OF DIGITAL SKIMMING ATTACKS
2y 0m to grant Granted Jul 28, 2026
Patent 12682076
SYSTEMS, APPARATUS AND METHODS FOR AUTOMATICALLY TESTING SECURITY DEVICES
2y 0m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
82%
Grant Probability
98%
With Interview (+15.1%)
3y 7m (~1y 5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 495 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month